Package Health

kolay/xlsx-stream

Streaming XLSX reader and writer for PHP and Laravel. Constant memory regardless of file size, direct S3 multipart streaming, optional born-indexed random access.

Latest v3.5.0PackagistPackagist

82%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

70

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

90

Health Score Breakdown

Maintainerscaution

Only one account has registry publish access, which creates publishing continuity risk; this is a caution because no organizational backing is shown to provide an obvious handoff path.

Project backingcaution

The repository is owned by an individual user rather than an organization, so there is no provided evidence of organizational maintenance capacity to compensate for the concentrated contributor and maintainer base.

Repo bus factorcaution

All 78 recent commits came from one contributor, with a 100% top-contributor share and only one active contributor, creating a meaningful continuity and abandonment risk.

Repo toolingcaution

Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a hygiene gap rather than a direct health failure because other repository and workflow signals are favorable.

Token permissionscaution

Both workflows lack top-level permissions declarations, while none declares top-level write access. The absence of explicit least-privilege permissions is a CI hardening gap and warrants caution.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Turgut Ahmet

Direct Dependencies

DependencyLast ReleaseScore
aws/aws-sdk-php
Version ^3.180
—
—
illuminate/support
Version ^10.0|^11.0|^12.0|^13.0
—
—

Weekly Downloads

Info

Last Published
27 days ago
Created
1 year ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform